Commvault backup job failing with Active Directory user to vCenter
search cancel

Commvault backup job failing with Active Directory user to vCenter

book

Article ID: 450093

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • Commvault backup jobs are failing in the Commvault UI with error:
    Error code: [91:465]

    Description: Unable to connect to vCenter server [vcenter_fqdn] as user [ad_user] from access node [commvault_node]. [Object reference not set to an instance of an object]
    Source: commvault_node, Process: vsdiscovery
  • Expired LDAPS cert:

    vCenter: /var/log/vmware/sso/vmware-identity-sts.log
    YYYY-MM-DDTHH:MM:SSZ ERROR sts[64:tomcat-http--25] [CorId=0c12b437-5214-4677-b4b2-79cd72899016] [com.vmware.identity.interop.ldap.OpenLdapClientLibrary] Server SSL certificate not trusted: Subject (CN=ldap_string)
    YYYY-MM-DDTHH:MM:SSZ WARN sts[64:tomcat-http--25] [CorId=0c12b437-5214-4677-b4b2-79cd72899016] [com.vmware.identity.interop.ldap.LdapErrorChecker] Error received by LDAP client: com.vmware.identity.interop.ldap.OpenLdapClientLibrary, error code: -1
    YYYY-MM-DDTHH:MM:SSZ WARN sts[64:tomcat-http--25] [CorId=0c12b437-5214-4677-b4b2-79cd72899016] [com.vmware.identity.idm.server.ServerUtils] cannot bind connection: [ldaps://ldap_server:636, CN=ldap_string]
    YYYY-MM-DDTHH:MM:SSZ ERROR sts[64:tomcat-http--25] [CorId=0c12b437-5214-4677-b4b2-79cd72899016] [com.vmware.identity.idm.server.ServerUtils] cannot establish ldap connection with URI: [ldaps://ldap_server:636] because [com.vmware.identity.interop.ldap.ServerDownLdapException] with reason [Can't contact LDAP server] therefore will try to attempt to use secondary URIs, if applicable

    YYYY-MM-DDTHH:MM:SSZ ERROR sts[52:tomcat-http--13] [CorId=48b807be-b9fd-4608-91c2-9117d1bf5435] [com.vmware.identity.interop.ldap.SslX509EqualityMatchVerificationCallback] Server SSL certificate verification failed for [Subject: CN=ldap_string] [SHA1 Fingerprint: EE:E7:CB:69:D9:FF:68:43:CE:67:AA:E1:97:BD:DF:B5:D3:1E:D0:57].: \nServer SSL certificate not a trusted certificate nor signed by a trusted certificate\n\nServer SSL certificate: [\n[\n  Version: V3\n  Subject: cert_parameters  Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11\n\n  Key:  Sun RSA public key, 2048 bits
    ...
     Validity: [From: Day MMM DD HH:MM:SS GMT YYYY,\n               To: Day MMM DD HH:MM:SS GMT YYYY]\

Environment

vCenter 8.X

Cause

DNS and expired LDAPS certificates can cause the noted error message and behavior. 

Resolution

  • Check that DNS is resolving all endpoints correctly (vCenter, Commvault, LDAP/AD).
  • Verify that LDAPS certs are not expired.

Additional Information

Renewing an expired LDAPS Cert if expired